# 反向代理站点配置模板
server {
    listen 443 ssl;
    server_name {{DOMAIN}};
    
    # SSL 证书配置
    ssl_certificate /etc/nginx/sites/{{SITE_NAME}}/ssl/cert.crt;
    ssl_certificate_key /etc/nginx/sites/{{SITE_NAME}}/ssl/private.key;
    
    # SSL 安全配置
    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512;
    ssl_prefer_server_ciphers off;
    
    # 安全头
    add_header Strict-Transport-Security "max-age=63072000" always;
    
    # 反向代理设置
    location / {
        proxy_pass {{PROXY_TARGET}};
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_buffering off;
        
        # 代理超时设置
        proxy_connect_timeout 30s;
        proxy_send_timeout 30s;
        proxy_read_timeout 30s;
    }
    
    # 健康检查端点（可选）
    location /health {
        access_log off;
        return 200 "healthy\n";
        add_header Content-Type text/plain;
    }
}